NUGET · SEPTEMBER 2026 · EARLY WARNING

ASP.NET Core Denial of Service Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
asp.net core (nuget)
Patched version
Not yet available
CVE-2026-69304GHSA-8CP2-47HG-MFGHGHSA-V3F6-M9J2-437P

An early warning has been issued for a potential denial of service vulnerability in ASP.NET Core. This issue is under investigation and no authoritative version range has been published yet.

What happened

An early warning has been issued regarding a potential denial of service vulnerability in ASP.NET Core. The vulnerability, tracked as CVE-2026-69304, GHSA-8CP2-47HG-MFGH, and GHSA-V3F6-M9J2-437P, involves improper handling of highly compressed data. This could allow an unauthorized attacker to perform a denial of service attack over a network.

The advisory for this vulnerability has been withdrawn as it is a duplicate of GHSA-8cp2-47hg-mfgh. At this time, no authoritative version range has been published, and no official fix has been released. It is recommended to monitor for any updates or patches related to this vulnerability in ASP.NET Core.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If asp.net core is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

At this time, no authoritative version range has been published for the affected components. It is recommended to monitor for any updates or patches related to this vulnerability in ASP.NET Core.

What should I do right now?

Monitor for any updates or patches related to this vulnerability in ASP.NET Core. Stay informed by consulting the primary sources provided for the latest information.

Has an official fix been released?

No official fix has been published yet. Continue to monitor the sources below for updates.

Sources

Join the 0Day waitlist →

← Back to all threats